{"_id":"@dzhechkov/skills-package-story-page","_rev":"5-e4663f3d7d70658022646147eafaac51","name":"@dzhechkov/skills-package-story-page","dist-tags":{"latest":"0.2.5"},"versions":{"0.2.1":{"name":"@dzhechkov/skills-package-story-page","version":"0.2.1","keywords":["agent-skills","codex","claude-code","package-documentation","landing-page","evidence","storytelling"],"author":{"name":"dzhechko"},"license":"MIT","_id":"@dzhechkov/skills-package-story-page@0.2.1","maintainers":[{"name":"dzhechkov","email":"jechkov.dmitriy@gmail.com"}],"homepage":"https://github.com/djd1m/dz-harness-hub/tree/main/packages/@dzhechkov/skills-package-story-page#readme","bugs":{"url":"https://github.com/djd1m/dz-harness-hub/issues"},"dist":{"shasum":"a85af5c8adc8e1c7b36608db6145a77fb789fbda","tarball":"https://registry.npmjs.org/@dzhechkov/skills-package-story-page/-/skills-package-story-page-0.2.1.tgz","fileCount":27,"integrity":"sha512-oiqIG0fmA/NR3lnp91vcl6dORXPHAP1ROM+jk7HcqezPJOzzvg6/SUQ8LRfaGM7MWZPpoukzRQHiecRSgfLNZA==","signatures":[{"sig":"MEQCIHTSvCXltDdfOutBqOghGEDdw9vdjAdGCdItJLjZc/T6AiA58QovObFbXzsVK6CsjZLB082bIC+W6Mg42ohINVCAbg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":847094},"type":"module","_from":"file:dzhechkov-skills-package-story-page-0.2.1.tgz","engines":{"node":">=22"},"scripts":{"test":"node --test test/*.test.mjs","render":"node package-story-page/scripts/render-story-page.mjs","extract":"node package-story-page/scripts/extract-package-evidence.mjs","verify-page":"node package-story-page/scripts/verify-story-page.mjs","verify-browser":"node package-story-page/scripts/verify-story-page-browser.mjs"},"_npmUser":{"name":"dzhechkov","email":"jechkov.dmitriy@gmail.com"},"_resolved":"/tmp/a493d1e389c102f4a7e1c317b71b737e/dzhechkov-skills-package-story-page-0.2.1.tgz","_integrity":"sha512-oiqIG0fmA/NR3lnp91vcl6dORXPHAP1ROM+jk7HcqezPJOzzvg6/SUQ8LRfaGM7MWZPpoukzRQHiecRSgfLNZA==","repository":{"url":"git+https://github.com/djd1m/dz-harness-hub.git","type":"git","directory":"packages/@dzhechkov/skills-package-story-page"},"_npmVersion":"10.9.4","description":"package-story-page — turn one existing package into an evidence-backed, examples-first, self-contained story page for non-specialists.","directories":{},"_nodeVersion":"22.22.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/skills-package-story-page_0.2.1_1787944524966_0.8000821896584516","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@dzhechkov/skills-package-story-page","version":"0.2.2","keywords":["agent-skills","codex","claude-code","package-documentation","landing-page","evidence","storytelling"],"author":{"name":"dzhechko"},"license":"MIT","_id":"@dzhechkov/skills-package-story-page@0.2.2","maintainers":[{"name":"dzhechkov","email":"jechkov.dmitriy@gmail.com"}],"homepage":"https://github.com/djd1m/dz-harness-hub/tree/main/packages/@dzhechkov/skills-package-story-page#readme","bugs":{"url":"https://github.com/djd1m/dz-harness-hub/issues"},"dist":{"shasum":"c76b891a5908d07e102cd70b3d368bf5e873df0e","tarball":"https://registry.npmjs.org/@dzhechkov/skills-package-story-page/-/skills-package-story-page-0.2.2.tgz","fileCount":27,"integrity":"sha512-L0UA/CHa4SHwNpp1Gm/IQquUsHiRVoihOxD9MYoVi3op/ghIR1BK6fx51BXaxd1oPrfFEk3iStEGPnjInwJQNA==","signatures":[{"sig":"MEQCIE/JFRNnfQGm1Ekis0eUKywRoV16rxd7jcttr5RoQH14AiBKAMiXAdrIN4bkLCvDZslofXqwJKDZ/tOUI3rspis5ZQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":847094},"type":"module","_from":"file:dzhechkov-skills-package-story-page-0.2.2.tgz","engines":{"node":">=22"},"scripts":{"test":"node --test test/*.test.mjs","render":"node package-story-page/scripts/render-story-page.mjs","extract":"node package-story-page/scripts/extract-package-evidence.mjs","verify-page":"node package-story-page/scripts/verify-story-page.mjs","verify-browser":"node package-story-page/scripts/verify-story-page-browser.mjs"},"_npmUser":{"name":"dzhechkov","email":"jechkov.dmitriy@gmail.com"},"_resolved":"/tmp/dcf65459d03676b8ca21804ac00fca28/dzhechkov-skills-package-story-page-0.2.2.tgz","_integrity":"sha512-L0UA/CHa4SHwNpp1Gm/IQquUsHiRVoihOxD9MYoVi3op/ghIR1BK6fx51BXaxd1oPrfFEk3iStEGPnjInwJQNA==","repository":{"url":"git+https://github.com/djd1m/dz-harness-hub.git","type":"git","directory":"packages/@dzhechkov/skills-package-story-page"},"_npmVersion":"10.9.4","description":"package-story-page — turn one existing package into an evidence-backed, examples-first, self-contained story page for non-specialists.","directories":{},"_nodeVersion":"22.22.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/skills-package-story-page_0.2.2_1787944904633_0.7898955405078527","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"@dzhechkov/skills-package-story-page","version":"0.2.3","keywords":["agent-skills","codex","claude-code","package-documentation","landing-page","evidence","storytelling"],"author":{"name":"dzhechko"},"license":"MIT","_id":"@dzhechkov/skills-package-story-page@0.2.3","maintainers":[{"name":"dzhechkov","email":"jechkov.dmitriy@gmail.com"}],"homepage":"https://github.com/djd1m/dz-harness-hub/tree/main/packages/@dzhechkov/skills-package-story-page#readme","bugs":{"url":"https://github.com/djd1m/dz-harness-hub/issues"},"dist":{"shasum":"64aa18b0448214396aae2cddfb6ca1b3c18780cc","tarball":"https://registry.npmjs.org/@dzhechkov/skills-package-story-page/-/skills-package-story-page-0.2.3.tgz","fileCount":27,"integrity":"sha512-wG3zfw5Qmw1S3dKccmBqjTD49Qv+WfgToVgVZGr+JmVBv2HDRmtyTjKrlh68ORwyANUfKy33m2lncw6Loe2Row==","signatures":[{"sig":"MEUCIQC4ZgVHW+I+RzaicrOa21su8IxLWQKFVKodTbeLL3yR2QIgTHGeaLSqhXy98VNNodfAVdjWQJiqgLgDX6swdKwGwF4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":847094},"type":"module","_from":"file:dzhechkov-skills-package-story-page-0.2.3.tgz","engines":{"node":">=22"},"scripts":{"test":"node --test test/*.test.mjs","render":"node package-story-page/scripts/render-story-page.mjs","extract":"node package-story-page/scripts/extract-package-evidence.mjs","verify-page":"node package-story-page/scripts/verify-story-page.mjs","verify-browser":"node package-story-page/scripts/verify-story-page-browser.mjs"},"_npmUser":{"name":"dzhechkov","email":"jechkov.dmitriy@gmail.com"},"_resolved":"/tmp/06b476f610383588e74fad660abf12d3/dzhechkov-skills-package-story-page-0.2.3.tgz","_integrity":"sha512-wG3zfw5Qmw1S3dKccmBqjTD49Qv+WfgToVgVZGr+JmVBv2HDRmtyTjKrlh68ORwyANUfKy33m2lncw6Loe2Row==","repository":{"url":"git+https://github.com/djd1m/dz-harness-hub.git","type":"git","directory":"packages/@dzhechkov/skills-package-story-page"},"_npmVersion":"10.9.4","description":"package-story-page — turn one existing package into an evidence-backed, examples-first, self-contained story page for non-specialists.","directories":{},"_nodeVersion":"22.22.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/skills-package-story-page_0.2.3_1788003813994_0.9191703387008856","host":"s3://npm-registry-packages-npm-production"}},"0.2.4":{"name":"@dzhechkov/skills-package-story-page","version":"0.2.4","keywords":["agent-skills","codex","claude-code","package-documentation","landing-page","evidence","storytelling"],"author":{"name":"dzhechko"},"license":"MIT","_id":"@dzhechkov/skills-package-story-page@0.2.4","maintainers":[{"name":"dzhechkov","email":"jechkov.dmitriy@gmail.com"}],"homepage":"https://github.com/djd1m/dz-harness/tree/main/packages/@dzhechkov/skills-package-story-page#readme","bugs":{"url":"https://github.com/djd1m/dz-harness/issues"},"dist":{"shasum":"5602653543204849b2eb4a9c3b60166f3ecdb3bd","tarball":"https://registry.npmjs.org/@dzhechkov/skills-package-story-page/-/skills-package-story-page-0.2.4.tgz","fileCount":27,"integrity":"sha512-7rzWihRHBUvc1Pm2zPZJCp6EIj5hXXkYEJHVLRSNEGejmWIwgVl0oPtxmZhnYZk7TwhOh6wfztOQLAfrLIMQaw==","signatures":[{"sig":"MEYCIQCBC4rC/hGVXmTN4nGdRH0XhPOkW1AeW2tACqZrRHT95QIhAK6W36jM96QuSM+/Qi9zPIbP09/heMaQp2/uhDnPHYxd","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":847163},"type":"module","_from":"file:dzhechkov-skills-package-story-page-0.2.4.tgz","engines":{"node":">=22"},"scripts":{"test":"node --test test/*.test.mjs","render":"node package-story-page/scripts/render-story-page.mjs","extract":"node package-story-page/scripts/extract-package-evidence.mjs","verify-page":"node package-story-page/scripts/verify-story-page.mjs","verify-browser":"node package-story-page/scripts/verify-story-page-browser.mjs"},"_npmUser":{"name":"dzhechkov","email":"jechkov.dmitriy@gmail.com"},"_resolved":"/tmp/e3f0f4305bbb2472fc5d5596d62d1efa/dzhechkov-skills-package-story-page-0.2.4.tgz","_integrity":"sha512-7rzWihRHBUvc1Pm2zPZJCp6EIj5hXXkYEJHVLRSNEGejmWIwgVl0oPtxmZhnYZk7TwhOh6wfztOQLAfrLIMQaw==","repository":{"url":"git+https://github.com/djd1m/dz-harness.git","type":"git","directory":"packages/@dzhechkov/skills-package-story-page"},"_npmVersion":"10.9.4","description":"package-story-page — turn one existing package into an evidence-backed, examples-first, self-contained story page for non-specialists.","directories":{},"_nodeVersion":"22.22.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/skills-package-story-page_0.2.4_1788025761585_0.15431176238474031","host":"s3://npm-registry-packages-npm-production"}},"0.2.5":{"_id":"@dzhechkov/skills-package-story-page@0.2.5","bugs":{"url":"https://github.com/djd1m/dz-harness/issues"},"dist":{"shasum":"7b4d307efa55a8cb30d0b9d9e2e0208fff16d362","tarball":"https://registry.npmjs.org/@dzhechkov/skills-package-story-page/-/skills-package-story-page-0.2.5.tgz","fileCount":27,"integrity":"sha512-ajjK+ZwYM59MIbqMHZybzkjbHlsdncT/wzQwJjMXOEY5xsm7MJoxRakUzgtPRwjon5epCVp67PT2u1G79O6oEQ==","signatures":[{"sig":"MEQCIAmbubFAxmLDoCd4LdzsQCzRMVItJB/urG1bZBPG4EeMAiADCko5QWWcuZ6eXo3evnOZFhTAjFaCNT+xlUyUF3MhNw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGR74RVP2x3iwShqt5KKu+fO2oXtDzskMSA9ED+1A8zVAiAOT2kyZuoxzNaMSMAQ71zeLrZqtgpDG3US3On531l+4A=="}],"unpackedSize":852942},"name":"@dzhechkov/skills-package-story-page","type":"module","_from":"file:dzhechkov-skills-package-story-page-0.2.5.tgz","author":{"name":"dzhechko"},"engines":{"node":">=22"},"license":"MIT","scripts":{"test":"node --test test/*.test.mjs","render":"node package-story-page/scripts/render-story-page.mjs","extract":"node package-story-page/scripts/extract-package-evidence.mjs","verify-page":"node package-story-page/scripts/verify-story-page.mjs","verify-browser":"node package-story-page/scripts/verify-story-page-browser.mjs"},"version":"0.2.5","_npmUser":{"name":"dzhechkov","email":"jechkov.dmitriy@gmail.com"},"homepage":"https://github.com/djd1m/dz-harness/tree/main/packages/@dzhechkov/skills-package-story-page#readme","keywords":["agent-skills","codex","claude-code","package-documentation","landing-page","evidence","storytelling"],"_resolved":"/tmp/baa97efa3993e8f5b18aa29c73fec465/dzhechkov-skills-package-story-page-0.2.5.tgz","_integrity":"sha512-ajjK+ZwYM59MIbqMHZybzkjbHlsdncT/wzQwJjMXOEY5xsm7MJoxRakUzgtPRwjon5epCVp67PT2u1G79O6oEQ==","repository":{"url":"git+https://github.com/djd1m/dz-harness.git","type":"git","directory":"packages/@dzhechkov/skills-package-story-page"},"_npmVersion":"10.9.4","description":"package-story-page — turn one existing package into an evidence-backed, examples-first, self-contained story page for non-specialists.","directories":{},"maintainers":[{"name":"dzhechkov","email":"jechkov.dmitriy@gmail.com"}],"_nodeVersion":"22.22.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/skills-package-story-page_0.2.5_1789294831539_0.1930100458201871"}}},"time":{"created":"2026-08-28T19:15:24.715Z","modified":"2026-09-13T10:20:31.778Z","0.2.1":"2026-08-28T19:15:25.112Z","0.2.2":"2026-08-28T19:21:44.797Z","0.2.3":"2026-08-29T11:43:34.117Z","0.2.4":"2026-08-29T17:49:21.739Z","0.2.5":"2026-09-13T10:20:31.642Z"},"bugs":{"url":"https://github.com/djd1m/dz-harness/issues"},"author":{"name":"dzhechko"},"license":"MIT","homepage":"https://github.com/djd1m/dz-harness/tree/main/packages/@dzhechkov/skills-package-story-page#readme","keywords":["agent-skills","codex","claude-code","package-documentation","landing-page","evidence","storytelling"],"repository":{"url":"git+https://github.com/djd1m/dz-harness.git","type":"git","directory":"packages/@dzhechkov/skills-package-story-page"},"description":"package-story-page — turn one existing package into an evidence-backed, examples-first, self-contained story page for non-specialists.","maintainers":[{"name":"dzhechkov","email":"jechkov.dmitriy@gmail.com"}],"readme":"# @dzhechkov/skills-package-story-page\n\nAn evidence-first skill for turning one existing package into a short story page ordinary people can\nunderstand. It shows a concrete input → process → inspectable output scenario before architecture,\ninstallation, cost, security, or FAQ copy.\n\n## What ships\n\n- `package-story-page/SKILL.md` — portable Codex/Claude workflow;\n- a bilingual routing evaluation, pinned Opus receipt, and isolated runner that separate a short story\n  page from the full tutorial-course sibling;\n- three compact contracts for evidence, story, and visual direction;\n- zero-runtime-dependency local extraction and rendering scripts plus a pinned, reproducibly built\n  parse5 semantic verifier whose bundle, provenance, and upstream licence texts ship inside the skill;\n- one self-contained HTML output with no remote fonts, images, scripts, or runtime fetch;\n- deterministic mutation and injection tests, including seventy-five live production mutants for the parse5\n  subset, item copy/bindings, disclosure ownership, raw-source CSS digest, pre-import integrity gate,\n  raw-slice authority, semantic input boundary, browser request verdict, named browser-startup failure,\n  and orphan-marker guard. The\n  checked-in mutation runner verifies a gate-owned scratch, copies it to a private ephemeral execution\n  root, and rebinds hashes only in that disposable copy. Every clean baseline executes both the live-\n  Firefox and unit-only lanes; browser-verifier mutations execute live Firefox. The retired 26-mutant hand-scanner set has an\n  explicit disposition ledger alongside 29 checkpoint-check rows (55 disposition rows total), instead\n  of pretending those dead guards still protect the product. Historical 27/30 live-registry checkpoints\n  are not disposition counts; the current live registry contains 75 guards.\n\n## Run directly\n\n```bash\nSKILL_ROOT=./package-story-page\nnode \"$SKILL_ROOT/scripts/extract-package-evidence.mjs\" --pkg <package> --json /tmp/evidence.json\n# Author package-story-brief/1 from the evidence, then:\nnode \"$SKILL_ROOT/scripts/render-story-page.mjs\" --brief /tmp/brief.json --out /tmp/site/index.html\nnode \"$SKILL_ROOT/scripts/verify-story-page.mjs\" --brief /tmp/brief.json --site /tmp/site/index.html --evidence /tmp/evidence.json --pkg <package>\n# Release gate when Firefox + geckodriver are installed:\nnode \"$SKILL_ROOT/scripts/verify-story-page-browser.mjs\" --site /tmp/site/index.html\n```\n\nThe static verifier is for output generated by this factory. It parses a deliberately closed HTML subset\nwith the shipped parse5 bundle, verifies exact semantic-module and bundle hashes before importing it, and never executes page\nJavaScript. It is not a general security scanner for arbitrary third-party HTML. The separate Firefox gate\nuses loopback servers and an observing proxy: a required second-origin probe must be seen and rejected before\nzero cross-origin requests from the canonical page can count as evidence. Canonical measurements accept\nonly the module-issued opaque receipt for that observation; a structurally identical object cannot forge it.\nThe recording proxy reads the exact module-issued probe target and its live hit count itself, so the call\nsite cannot substitute `true, 0` for the observation.\nThe driver profile root is created outside the checked package tree, using Firefox Snap's writable\nper-user common directory when present and the system temporary directory otherwise, and is removed\nafter the driver exits. If geckodriver cannot start, the command exits nonzero with\n`BROWSER CHECK NOT RUN — <driver reason>`; instrument unavailability is never reported as a pass.\nIts bounded RU and EN lane\nuses real Enter/Space input, checks stable accessible names before and after activation, and measures\nthe declared 320/390/768/1440 viewports after a clean completed navigation.\n\nBefore any local ESM module evaluates, the wrapper reads and SHA-pins all five loaded local inputs:\nsemantic verifier, parse5 bundle, evidence extractor, renderer, and shared schema. The static import-graph gate asks Node's `SourceTextModule` parser for module requests and permits only\ncontained relative `.mjs` edges plus exact `node:crypto`; it rejects renderer, package, URL, bare, and\nother-builtin resolution. The separate lexical capability diagnostic owns only its bounded named corpus.\nIf that isolated parser cannot be launched or returns an empty, incompatible, signalled, non-syntax, or\nuntyped result, the graph gate fails closed with a named parser-unavailable reason. A typed syntax/source\nrejection remains hard even with a nonzero exit; the bounded lexer never substitutes for graph authority.\nThe child receives a copied environment with caller `NODE_OPTIONS` removed so launch preloads cannot\nsilently downgrade a valid parse; the parent runtime itself remains inside the trusted local preflight boundary.\nNeither mechanism claims to confine arbitrary or deliberately re-authorised JavaScript. The reviewed\nexact-byte hashes and caller-side signed artifact preflight remain the executable authority.\n\nFor repository routing maintenance, run `package-story-page/evals/run-pair-routing.mjs` with `--out`.\nAn installed standalone copy can pass the sibling's `SKILL.md` through `--sibling-skill`; expected owners\nnever enter the judge prompt.\n\n## Honest scope\n\nStatic checks prove current-file SHA and bounded line-range provenance, exact numeric token/non-self context support\non one cited line, explicit synthetic-example labelling, package identity, exact authored-field placement,\nsource-id closure, per-item evidence/status ownership with no hidden, orphan, or unexpected owners, exact\nfield-owner cardinality, and no extra non-whitespace visible prose after an independently enumerated\nexact-value renderer-chrome multiset is consumed. Classes, navigation placement and status attributes never\ngrant a chrome exemption. It also proves exact\ndirect-main section topology, brief-ordered item placement/containers, a brief-derived exact tag multiset,\nexact class/ID/category ownership, first-mechanism-only initial-open state, and non-nested direct-child\nnative disclosures. The shipped parse5 authority rejects parse\nerrors or browser repairs, synthesized or unlocated nodes, foreign namespaces, comments, and every element\nor attribute outside the emitted closed subset. Source links must be brief-declared absolute HTTPS anchors\nwith `rel=\"noreferrer\"` inside the source disclosure. The sole `<style>` element is accepted only when the\nSHA-256 of its exact parse5-bounded source bytes matches the verifier-owned digest. Separate bounded checks\ncover focus outlines, universal reduced-motion suppression, responsive one-column reflow without\n`overflow: hidden|clip`, safe wrapping, synthetic labels, and visual directions. The four CSS policy\npredicates are tested independently from the exact stylesheet digest; overall verification still requires\nboth the digest authority and every policy receipt. They do not prove that a claim is true outside the\npackage, that a page is beautiful, that it converts, or that it fully conforms to WCAG. Those remain\ncontent/visual review responsibilities. Local package documentation can itself contain false claims:\nits SHA proves which package bytes made the statement, not that the statement is independently true.\nEvidence files are read as fatal UTF-8 through non-symlink descriptors, with a 1 MiB per-file and\n8 MiB aggregate provenance ceiling. Brief and evidence object graphs deeper than 64 levels fail closed\nbefore schema or canonical traversal. These are resource and decoding boundaries, not truth guarantees.\nThe decimal-token gate recognizes Unicode numerals; spelled-out number words remain semantic review.\nA local external receipt must contain its exact URL and check\ndate, but that still does not prove a fetch or remote truth. The separate Firefox gate measures\nhorizontal and internal scroll-container overflow at exact 320, 390, 768, and 1440 px content widths\nand checks rendered focus on every link/disclosure plus field, disclosure-label, and dark-surface\nevidence/status/kicker contrast; it requires\nsystem browser binaries but no npm runtime dependency. `npm test` runs this browser gate by default;\n`PACKAGE_STORY_SKIP_BROWSER=1 npm test` is an explicitly weaker unit-only lane.\n\n`package-tutorial-factory` is the right tool for a full course with exercises and a final test. This\npackage deliberately produces the shorter story/landing artifact.\n\nOnly the root signed manifest and root generated SBOM are self-excluded from the manifest file list to avoid\nrecursive self-hashes. Same-named files below nested directories are ordinary signed content. `dz verify-pack`\nfirst authenticates the manifest, then derives the one canonical CycloneDX\ndocument from those signed entries and requires `sbom.json` to match it byte-for-byte. A missing, malformed,\nduplicated, renamed, re-hashed, or metadata-modified component therefore fails consumer verification too,\nnot only CI. Delivery tests run that gate on both the source package and the unpacked npm tarball, and the\ntarball preflight completes before its tests, adapters, or pipeline execute. Direct unverified execution or\nsame-user/concurrent mutation after that preflight is outside this local/offline authenticity boundary.\nByte-stable files carry ordinary raw SHA-256 entries. The packer-rewritten `package.json` component does\nnot present its canonical JSON verification digest as a raw file hash: it uses explicit\n`dz:canonical-json-sha256-v2` and `dz:digest-basis=package-json-ordered-conditions-v2` properties.\nOrdinary metadata keys are sorted, while `exports`, `imports`, and `typesVersions` descendant key order\nis preserved so first-match entry-point semantics remain authenticated. Unsigned state is role-classified:\n`.git` entries of any type and directory/symlink `node_modules`, `.agentic-qe`, or `.dz`; same-named\nordinary files other than `.git` remain signed. The exact npm tarball contains none of those state entries.\nMEASURED by the 64-case `harness-core/test/sign.test.ts` lane plus the 7 canonical and 9 differential\nhash cases: malformed, duplicate-key, or precision-losing root `package.json` JSON is refused before\ncurrent/v3 signing and fails current/v3 verification; it is never raw-hashed under that canonical label.\nThis package is signed with manifest/SBOM format v3. Existing v1/v2 packs remain readable through\ncompatibility verification; current SBOM output never emits the historical non-standard hash label.\nFor authenticated use this is a caller-side precondition: run `dz verify-pack` successfully before\nprojection or execution; `dz init --skills-dir` does not authenticate a source tree by itself.\n\nThe signed consumer object is the unpacked pnpm tarball. pnpm removes the repository-only\n`prepublishOnly` lifecycle hook from the published `package.json`, so running `dz verify-pack` directly\nagainst this authoring directory is expected to fail on `package.json`; the delivery gate proves that\nsingle removal is the complete metadata delta and verifies the exact unpacked artifact instead.\n\n## Development\n\n```bash\nnpm test\n# Repository full-qe-extended discrimination lane (requires dz):\ndz mutation-gate --package . --registry test/mutation-registry.json --rebaseline per-entry\n```\n\nVersion 0.2.5 is staged locally. No npm publication is implied by the repository version.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}